Feed/CVE-2025-1974
CVE-2025-1974CRITICALCVSS 9.8

CVE-2025-1974

Published Mar 24, 2025·Updated Jun 17, 2026

NVD Description

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Public Exploits & PoCs17 found

PoC: IngressNightmare-POCs

CVE-2025-1974

4

PoC: nginxnightmare

IngressNightmare-POC CVE-2025-1974 https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities#how-did-we-discover-ingressnightmare-24

3

PoC: CVE-2025-1974

Poc for Ingress RCE

2

PoC: IngressNightterror

My view on IngressNightmare vulnerability (CVE-2025-1974)

1

PoC: CVE-2025-1974

ingress-nginx admission controller RCE escalation PoC

PoC: CVE-2025-1974-PoC-exploit

Kubernetes Ingress-nginx RCE (IngressNightmare)

PoC: Blackash-CVE-2025-1974

CVE-2025-1974

PoC: CVE-2025-1974

WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제

PoC: CVE-2025-1974-go

Exploit CVE-2025-1974 with a single file.

PoC: CVE-2025-1974

CVE-2025-1974 PoC 코드

PoC: POC-IngressNightmare-CVE-2025-1974

POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974

PoC: ingress-nightmare

IngressNightmare (CVE-2025-1974)

PoC: CVE-2025-1974

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.

PoC: CVE-2025-1974-poc

PoC of CVE-2025-1974, modified from the world-first PoC~

PoC: ingressnightmare-detection-poc

Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.

PoC: IngressNightmare-RCE-POC

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.

PoC: IngressNightmare-CVE-2025-1974

Exploit for CVE-2025-1974

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free